PT-2026-35063 · 4Gaboards · 4Gaboards
CVE-2026-41418
·
Published
2026-04-24
·
Updated
2026-04-25
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
4ga Boards versions prior to 3.3.5
Description
4ga Boards is a boards system for realtime project management. The software allows user enumeration through a timing side-channel in the login endpoint '/api/access-tokens'. The server responds significantly faster when an invalid username or email is provided compared to when a valid one is used with an incorrect password. This difference occurs because the server executes the
bcrypt.compareSync() function only when a valid user is identified, creating a detectable timing gap that can be used to verify the existence of users.Recommendations
Update to version 3.3.5.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
4Gaboards